Close Menu
TechurzTechurz

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Microsoft hires the team of Sequoia-backed AI collaboration platform, Cove

    March 18, 2026

    This startup wants to make enterprise software look more like a prompt

    March 18, 2026

    The leaderboard “you can’t game,” funded by the companies it ranks

    March 18, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Microsoft hires the team of Sequoia-backed AI collaboration platform, Cove
    • This startup wants to make enterprise software look more like a prompt
    • The leaderboard “you can’t game,” funded by the companies it ranks
    • Sequen snags $16M to bring TikTok-style personalization tech to any consumer company
    • Why Garry Tan’s Claude Code setup has gotten so much love, and hate
    • Niv-AI exits stealth to wring more power performance out of GPUs
    • H&M wants to make clothing from CO2 using this startup’s tech
    • Fuse raises $25M to disrupt aging loan origination systems used by US credit unions
    Facebook X (Twitter) Instagram Pinterest Vimeo
    TechurzTechurz
    • Home
    • AI
    • Apps
    • News
    • Guides
    • Opinion
    • Reviews
    • Security
    • Startups
    TechurzTechurz
    Home»Security»If you use OneDrive to upload files to ChatGPT or Zoom, don’t
    Security

    If you use OneDrive to upload files to ChatGPT or Zoom, don’t

    TechurzBy TechurzMay 28, 2025No Comments1 Min Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    ChatGPT R, robotic hand typing on keyboard
    Share
    Facebook Twitter LinkedIn Pinterest Email


    OneDrive File Picker is a Microsoft-provided tool that lets websites and web apps integrate with a user’s OneDrive account to allow uploading, browsing, and selecting OneDrive files directly from the app.

    An over-privileged OAuth trap

    This broad access stems from a limitation in Microsoft’s OAuth implementation within File Picker that researchers described as “a lack of fine-grained permissions scopes.”

    Jason Soroko, senior fellow at Sectigo, calls the oversight an over-privileged OAuth trap. “Microsoft’s OneDrive File Picker encourages third-party web apps to request broad files,” he said. “Once issued, those long-lived tokens are often cached in localStorage or back-end databases without any encryption, potentially allowing attackers to trawl an entire tenant’s data.”

    OneDrive File Picker’s OAuth implementation requests broad scopes, instead of fine-grained, file-level scopes, allowing users and developers to restrict access to only the files explicitly selected.

    ChatGPT dont Files OneDrive upload Zoom
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleI just used Veo 3 to create a wild AI video and it’s easier than you think
    Next Article How to set up your own article archiving service – and why I did (RIP, Pocket)
    Techurz
    • Website

    Related Posts

    Opinion

    Particle’s AI news app listens to podcasts for interesting clips so you you don’t have to

    February 23, 2026
    Opinion

    Why these startup CEOs don’t think AI will replace human roles

    February 19, 2026
    Opinion

    What the Epstein files reveal about EV startups and Silicon Valley

    February 15, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    College social app Fizz expands into grocery delivery

    September 3, 20252,288 Views

    A Former Apple Luminary Sets Out to Create the Ultimate GPU Software

    September 25, 202516 Views

    The Reason Murderbot’s Tone Feels Off

    May 14, 202512 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    College social app Fizz expands into grocery delivery

    September 3, 20252,288 Views

    A Former Apple Luminary Sets Out to Create the Ultimate GPU Software

    September 25, 202516 Views

    The Reason Murderbot’s Tone Feels Off

    May 14, 202512 Views
    Our Picks

    Microsoft hires the team of Sequoia-backed AI collaboration platform, Cove

    March 18, 2026

    This startup wants to make enterprise software look more like a prompt

    March 18, 2026

    The leaderboard “you can’t game,” funded by the companies it ranks

    March 18, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 techurz. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.